CVE-2026-52739 | ZcashFoundation Zebra/Zebra State up to 4.4.x Non Finalized State chain.rs Chain::push assertion

SecurityVulns

A vulnerability marked as critical has been reported in ZcashFoundation Zebra and Zebra State up to 4.4.x. Affected by this vulnerability is the function Chain::push of the file zebra-state/src/service/non_finalized_state/chain.rs of the component Non Finalized State. Performing a manipulation results in reachable assertion.

This vulnerability is identified as CVE-2026-52739. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More